Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Thu Sep 12, 2013 4:56 pm 
Offline
Junior Member

Joined: Wed Apr 25, 2012 5:38 pm
Posts: 47
Hi Guys been having problems for a few weeks with Avast Anti Virus who have blacklisted my site. Google or no other virus/malware scanners have black listed the site.

Many of my site users are Avast users and traffic and income is down for me. I have been chasing this up with Avast who now say the following.

Quote:
The avast alert was for hxtp://www.whitbyseaanglers.co.uk/wp-in ... p-mail.php
Code hick-up
ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js?ver=3.6.1 benign
[nothing detected] (script) ajax.googleapis.com/ajax/libs/jquery/1/jquery.min.js?ver=3.6.1
status: (referer=wXw.whitbyseaanglers.co.uk/wp-includes/wp-mail.php)saved 92629 bytes ae49e56999d82802727455f0ba83b63acd90a22b
info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
info: [decodingLevel=0] found JavaScript
suspicious:
Read how your site might have been infected: http://digwp.com/2009/06/xmlrpc-php-security/
Core code from WP is mostly secure and updated regularly against insecurities and vulnerabilities,
but there are many plug-ins and extemsions for WP that are less secure and may be vulnerable.
The xmlrpc-php-security issues should be taken up with your hoster as these are web server attacks.
See code
46:< link rel="EditURI" type="application/rsd+xml" title="RSD" href="htxp://www.whitbyseaanglers.co.uk/xmlrpc.php?rsd" />
47:< link rel="wlwmanifest" type="application/wlwmanifest+xml" href="htxp://www.whitbyseaanglers.co.uk/wp-includes/wlwmanifest.xml" />
There is also an issue with this backlink: https://www.eff.org/https-everywhere/at ... n.com.html
see:
GET /p/flash/moogaloop/5.5.0b29/moogaloop.swf?clip_id=62537288 HTTP/1.1
Host: a.vimeocdn.com
HTTP/1.1 200 OK
Content-Type: application/x-shockwave-flash

polonus


Basically this makes no sense to me at all and I dont know what steps are needed to tidy up the site.

Please please please help.


Top
   
PostPosted: Thu Sep 12, 2013 6:46 pm 
Offline
Senior Member

Joined: Mon Jan 02, 2012 12:45 pm
Posts: 365
glennk,
Avast seems to think your wp-mail.php file is (or was) infected. They also don't like that you haven't changed your WordPress code to remove the xmlrpc.php link in your site's HTML <head>.

You need to make sure that your wp-mail.php file is clean. If you're not using the wp-mail.php code then you should remove or rename the file.

Read the link they provided (http://digwp.com/2009/06/xmlrpc-php-security/) to see how to get rid of the xmlrpc.php issue.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: Dweeber and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group